Skip to main content

AVP, Product Security Architect

Stamford, CT

Apply

Overview

  • Location: Stamford, CT
  • Salary: 115,000.00 - 200,000.00 USD Annual

About Us

Synchrony is more than a financial services company, we’re a team of passionate innovators committed to delivering best-in-class solutions that support millions of customers across the U.S. With a bold focus on technology, data, and digital innovation, we create meaningful experiences that simplify lives and enable financial wellness.

When you join Synchrony, you become part of an inclusive culture where your voice matters, your growth is championed, and your work drives impactful results.

Job Description

Job ID
2600525
Category
Technology
Date posted
03/23/2026


Role Summary/Purpose:

Synchrony is seeking an AVP, Product Security Architect to provide enterprise-level product security architecture leadership across Synchrony’s application and SaaS ecosystem. This role operates at L11 scope—setting direction, defining standards, and driving adoption at scale—while partnering closely with product and engineering leaders to embed security into product strategy and modern software delivery.

The AVP will lead the definition of an Application Security Blueprint (reference architectures, approved patterns, and engineering guardrails) and will influence outcomes across multiple portfolios by enabling teams to design and deliver software that is secure-by-design, resilient, and compliant.

Essential Responsibilities:

  • Set product security architecture direction for assigned portfolios, aligning security architecture decisions with Synchrony technology strategy, risk appetite, and regulatory expectations.
  • Own and evolve the Application Security Blueprint: enterprise application security standards, reference architectures, reusable patterns, and guardrails that enable consistent secure engineering across teams.
  • Serve as a strategic partner to product and engineering leadership, influencing roadmaps and operating models to ensure security is built-in (not bolted-on) and delivery teams can move quickly with well-defined paved roads.
  • Lead architecture governance for product/application security:
    • establish review criteria and decision frameworks
    • perform design reviews and approve/drive remediation plans
    • manage exceptions with documented risk acceptance, compensating controls, and time-bound closure
  • Drive threat modeling at scale by defining methodology and minimum expectations, and by facilitating modeling for high-risk initiatives—explicitly documenting trust boundaries, data flows, abuse cases, and security requirements.
  • Define and standardize API security architectures (north-south and east-west), including authentication/authorization, token strategy, schema and input validation, anti-automation protections, and rate limiting/throttling patterns.
  • Define patterns for service-to-service security controls in distributed systems, including workload identity, authorization, mTLS, secrets handling, and policy enforcement—ensuring controls are practical for engineering adoption.
  • Influence and enable secure SDLC and platform controls with engineering enablement in mind (security requirements, pipeline guardrails, dependency/supply-chain controls, secure configuration guidance), partnering with platform teams to operationalize.
  • Establish and track measurable outcomes (e.g., blueprint adoption, recurring architecture risks, API posture improvements, exception burn-down, control coverage for critical apps) and provide clear executive-level reporting.
  • Act as a coach and multiplier: mentor engineers and architects, elevate secure design skills across teams, and improve security decision-making through clear documentation and reusable assets.
  • Perform other duties and/or special projects as assigned.

Qualifications/Requirements:

  • 7+ years in security architecture/engineering, with deep focus on application/product security in modern software environments.
  • Demonstrated ability to operate at an enterprise influence level: setting standards, driving cross-team adoption, and aligning stakeholders with differing priorities.
  • Strong hands-on knowledge of application and service security fundamentals: authentication/authorization, session/token security, cryptography concepts, secrets management, secure logging/monitoring design, and secure data handling.
  • Proven experience leading threat modeling and producing strong architecture artifacts (DFDs, trust boundaries, security requirements, risk assessments).
  • Strong knowledge of API security and common web/service risks (e.g., OWASP Top 10 / API Security Top 10), with the ability to translate risks into enforceable patterns.
  • Excellent communication skills—able to present clearly to engineering teams and senior leaders, and to produce high-quality architecture documentation.
  • Track record of driving security with product teams: embedding security into product planning, influencing roadmaps, defining “definition of done” security requirements, and improving time-to-market through paved-road patterns.
  • Experience securing and integrating SaaS applications, including SSO/federation (SAML/OIDC), tenant and data isolation considerations, audit logging, and shared responsibility alignment.
  • Experience implementing service-to-service security patterns at scale (workload identity, mTLS, authorization, policy-as-code concepts).
  • Experience operationalizing security standards into engineering consumables (shared libraries, templates, reference implementations, runbooks).
  • Familiarity with CI/CD-based security enablement (SAST/DAST/SCA, secrets scanning, gating/exception workflows) and vulnerability management operating models.
  • Experience supporting regulated environments and mapping architecture controls to policies/standards.
  • Certifications (preferred): CISSP, CCSP, CSSLP (or equivalent).
  • Ability and flexibility to travel for business as required

Desired Characteristics:

  • Threat modeling tooling;
  • API gateways/policy enforcement; identity and federation (SSO, SAML, OIDC);
  • application security testing (SAST/DAST/SCA/secret scanning);
  • CI/CD tooling (e.g., GitHub/Jenkins); vulnerability management platforms; logging/monitoring;
  • service mesh/mTLS patterns; secrets management solutions

Grade/Level: 11

The salary range for this position is 115,000.00 - 200,000.00 USD Annual and is eligible for an annual bonus based on individual and company performance.

Actual compensation offered within the posted salary range will be based upon work experience, skill level or knowledge.

Salaries are adjusted according to market in CA, NY Metro and Seattle.

Eligibility Requirements:

  • You must be 18 years or older
  • You must have a high school diploma or equivalent
  • You must be willing to take a drug test, submit to a background investigation and submit fingerprints as part of the onboarding process
  • You must be able to satisfy the requirements of Section 19 of the Federal Deposit Insurance Act.
  • New hires (Level 4-7) must have 9 months of continuous service with the company before they are eligible to post on other roles.  Once this new hire time in position requirement is met, the associate will have a minimum 6 months’ time in position before they can post for future non-exempt roles.  Employees, level 8 or greater, must have at least 18 months’ time in position before they can post.  All internal employees must consistently meet performance expectations and have approval from your manager to post (or the approval of your manager and HR if you don’t meet the time in position or performance expectations).

Legal authorization to work in the U.S. is required.  We will not sponsor individuals for employment visas, now or in the future, for this job opening. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. 

Our Commitment:

When you join us, you’ll be part of an inclusive culture where your individual skills, experience, and voice are not only heard – but valued. Together, we’re building a future where we can all belong, connect, and turn ideals into action. More than 50% of our workforce is engaged in our Employee Resource Groups (ERGs), where community and passion intersect to offer a safe space to learn and grow.

This starts when you choose to apply for a role at Synchrony. We ensure all qualified applicants will receive consideration for employment without regard to age, race, color, religion, gender, sexual orientation, gender identity, national origin, disability, or veteran status. We’re proud to have an award-winning culture for all. 

Reasonable Accommodation Notice:

  • Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
  • If you need special accommodations, please call our Career Support Line so that we can discuss your specific situation. We can be reached at 1-866-301-5627.   Representatives are available from 8am – 5pm Monday to Friday, Central Standard Time

Job Family Group:

Information Technology

Our Locations

Virtual

Dallas Location

Dallas, TX

Seattle Location

Seattle, WA

bosie location

Boise, ID

San Francisco location

San Francisco, CA

bosie location

Rapid City, SD

Phoenix location

Phoenix, AZ

Minneapolis location

Minneapolis, MN

St Paul location

St. Paul, MN

canton location

Canton, OH

baltimore location

Baltimore, MD

washington location

Washington, DC

boston location

Boston, MA

Delhi NCR location

Delhi NCR, India

Kolkata location

Kolkata, India

Pune location

Pune, India

Chennai location

Chennai, India

Hybrid United States

Alpharetta Location

Alpharetta, GA

Bentonville Location

Bentonville, AR

Charolotte location

Charlotte, NC

Chicago location

Chicago, IL

Cincinnati location

Cincinnati, OH

Costa Mesa location

Costa Mesa, CA

New York location

New York, NY

orlando location

Orlando, FL

salt lake city location

Salt Lake City, UT

Stamford location

Stamford, CT

Hybrid International

cebu city Location

Cebu City, Phillippines

hyderabad Location

Hyderabad, India

Manila location

Manila, Phillippines

Investing in You

Our benefits and rewards reflect our culture and our values. We listen closely to our employees and continuously evolve how we support them. Putting people first means empowering you to bring your best self to work every day.

Whether you’re joining us to explore new opportunities, grow your financial security, enjoy greater flexibility, or all of the above, we’re committed to helping you achieve your unique ambitions.

Learn More

piggy bank icon

Retirement Plan

Secure your future with plans that also include an employer match.

core curriculum

Work - Life Harmony

We believe work should complement your life, not compete with it. With flexible options and understanding, we help you create a balance that works for you, allowing you to thrive both personally and professionally.

paid time off

Health & Wellness

Your health matters. From physical to mental well-being, we provide resources and support to keep you feeling your best, so you can focus on what matters most – both at work and in life.

paid time off

Paid Time Off

Everyone needs time to rest and recharge. We offer generous paid time off so you can take the breaks you deserve, whether that means vacation, personal days, observed holidays, or simply stepping away to refresh.

financial wellbeing

Financial Wellbeing

Financial peace of mind is key to living well. Our programs are designed to help you plan, save, and grow your financial future with confidence and ease.

Living Our Values

Our Way of Working

We’re proud to offer you flexibility. At Synchrony, our way of working allows you to have the option to work from home, near one of our Hubs or come into one of our offices. Occasionally you may be required to commute or travel for in person engagement activities such as business or team meetings, training and culture events.

Learn More

Employee Resource Groups (ERGs)

More than 50% of our workforce is actively engaged with our 8 Employee Resource Group (ERGs). These groups are open for everyone to join, regardless of level, background, or life experiences, so all employees can have the opportunity to be passionate about their interests while fostering connections and driving meaningful initiatives at work. Their ideas turn into actions through passion and help Synchrony be a place where everyone feels welcomed, valued and accepted.

Learn More

Our Recent Awards & Accolades

  • intern day award
  • best workplaces asia award
  • fortune 100 award
  • bgptw award
  • financial service award

You have not viewed any jobs yet.

You have not saved any jobs yet.

Join our Talent Community to stay connected!

Sign up for or Talent Community to stay in the loop about new jobs and the latest Synchrony News.

Interested InPlease select a category or location option. Click “Add” to create your job alert.

By submitting your information, you acknowledge that you have read our privacy policy and consent to receive email communication from Synchrony.